gitwtfhub

wtf is awesome-reverse-engineering-and-malware-analysis?

zx41r/awesome-reverse-engineering-and-malware-analysis — explained in plain English

Analysis updated 2026-05-18

59ShellAudience · researcherComplexity · 1/5LicenseSetup · easy

TL;DR

A carefully curated and continuously verified list of reverse engineering and malware analysis resources, organized into guided learning tracks.

Mindmap

mindmap
  root((RE and malware list))
    What it does
      Curated resource list
      Verified links only
      Guided learning tracks
    Topics covered
      Reverse engineering tools
      Malware analysis and DFIR
      Exploit development
      Fuzzing and firmware
    Tech stack
      Shell scripts
      Markdown docs
    Use cases
      Learn reverse engineering
      Study malware analysis
      Find CTF resources
    License
      CC0 public domain

Code map

Detail Auto

An interactive map of this repo's files and how they connect — its source is parsed live in your browser. Click Visualize to build it.

filefunction / class

Why would anyone build with this?

REASON 1

Follow a guided track to learn Windows malware analysis from scratch.

REASON 2

Find verified, up to date tools for static and dynamic binary analysis.

REASON 3

Look up researcher blogs and writeups on specific reverse engineering topics.

REASON 4

Discover DFIR and threat intelligence resources organized by topic.

What's in the stack?

ShellMarkdown

How it stacks up

zx41r/awesome-reverse-engineering-and-malware-analysisbyjoey/xray-cf-litecode-leafy/g2rayxcodeleafy
Stars595860
LanguageShellShellShell
Setup difficultyeasymoderatemoderate
Complexity1/53/53/5
Audienceresearcherops devopsdeveloper

Figures from each repo's GitHub metadata at analysis time.

How do you spin it up?

Difficulty · easy Time to first run · 5min
Released under CC0 1.0, meaning it is dedicated to the public domain and can be used for any purpose with no restrictions.

Wtf does this do

This repository, nicknamed unpacked, is a curated list of resources for reverse engineering and malware analysis. Its main selling point is quality control: every linked resource has actually been opened and checked before being added, and it gets removed the moment it goes dead or stale, instead of accumulating one word notes or vague filler entries the way many similar lists do. The list covers a wide range of topics: static and dynamic analysis, unpacking, exploit development, fuzzing, firmware and embedded systems, mobile platforms, operating system internals, digital forensics and incident response, and threat intelligence, along with researcher blogs and standalone writeups that larger lists tend to miss. Each entry is tagged with its difficulty level, its type such as tool, blog, writeup, course, video, paper, or book, and any relevant notes like whether it requires payment or signup, or if it is written in a language other than English. For newcomers, the README suggests specific guided tracks rather than reading the whole list top to bottom, such as a path through Windows malware analysis, Linux and ELF reversing, exploit development, firmware and embedded work, mobile app internals, or anti-analysis techniques like obfuscation and anti-debugging. The full topic map is organized into folders covering foundations, reverse engineering tools, malware analysis, malware development for study purposes, exploit development, fuzzing, firmware, mobile, operating system internals, anti-analysis, living off the land techniques, DFIR, threat intelligence, and learning platforms like CTFs. The README also lists several community forums where reverse engineers post first, including some Chinese language communities alongside English ones like Reddit's reverse engineering and malware subreddits. The project is released under CC0 1.0, meaning it is dedicated to the public domain with no restrictions.

Yoink these prompts

Prompt 1
Recommend a starting track from this list for someone new to Linux and ELF reversing.
Prompt 2
Help me find fuzzing tools and resources listed in this repository's fuzzing section.
Prompt 3
Explain what tags like intro, working, and deep mean in this list and how to use them.
Prompt 4
Point me to the anti-analysis section resources for learning about packers and anti-debug techniques.

Frequently asked questions

wtf is awesome-reverse-engineering-and-malware-analysis?

A carefully curated and continuously verified list of reverse engineering and malware analysis resources, organized into guided learning tracks.

What language is awesome-reverse-engineering-and-malware-analysis written in?

Mainly Shell. The stack also includes Shell, Markdown.

What license does awesome-reverse-engineering-and-malware-analysis use?

Released under CC0 1.0, meaning it is dedicated to the public domain and can be used for any purpose with no restrictions.

How hard is awesome-reverse-engineering-and-malware-analysis to set up?

Setup difficulty is rated easy, with roughly 5min to a first successful run.

Who is awesome-reverse-engineering-and-malware-analysis for?

Mainly researcher.

View the repo → Decode another repo

This repo across BitVibe Labs

Don't trust strangers blindly. Verify against the repo.